This website requires JavaScript.
Explore
Help
Register
Sign In
kai
/
pingu-concerts
Watch
1
Star
0
Fork
0
You've already forked pingu-concerts
Code
Issues
10
Pull Requests
Actions
Packages
Projects
Releases
Wiki
Activity
Page:
Security
Pages
Android App
Architecture
Backup and Recovery
Badges and Patches
Comments and Community
Concerts
Configuration
Database
Deployment
Development Setup
Firebase Setup Prompt
Firebase
Gitea Workflow
Home
Issues and Bug Reporting
Photos and Uploads
Push Notifications
Roadmap
Security
Troubleshooting
Users and Profiles
Venues
Code
Clone
HTTPS
Tea CLI
1
Security
MetalCircle Codex Bot edited this page
2026-09-15 01:09:10 +02:00
Table of Contents
Security
Security
Secrets bleiben in
.env
oder lokalen Secret Stores und werden nie committed oder geloggt.
Gitea-Tokens werden ausschließlich im Backend verwendet; Bot-Identitäten und Git-Zugriff sind getrennt.
Session-Cookies sind HttpOnly; Logout löscht Session- und Push-Gerätezuordnungen.
Bugreport-Kontext ist eine enge Allowlist; Query-Parameter, Cookies, Authorization-Header und FCM-Tokens werden ausgeschlossen.
Uploads werden serverseitig geprüft, verarbeitet und über Berechtigungen geschützt.
Benutzer-, Freundes-, Blockierungs- und Sichtbarkeitsregeln gelten auch bei Konzertdaten.
Firebase-Konfigurationsdateien, private Schlüssel, Dumps und lokale Uploads gehören nicht in Git.
Produktionsdaten und Produktions-Secrets werden in lokaler Entwicklung nicht verwendet.
Delete Page
Deleting the wiki page "Security" cannot be undone. Continue?
No
Yes